Installations
npm install @toruslabs/constants
Developer Guide
Typescript
Yes
Module System
CommonJS
Min. Node Version
>=18.x
Node Version
20.16.0
NPM Version
lerna/8.1.9/node@v20.16.0+arm64 (darwin)
Score
94.9
Supply Chain
68.2
Quality
85.8
Maintenance
100
Vulnerability
100
License
Releases
Contributors
Unable to fetch Contributors
Languages
TypeScript (94.13%)
JavaScript (3.25%)
Dockerfile (1.48%)
HTML (1.14%)
Developer
torusresearch
Download Statistics
Total Downloads
1,321,569
Last Day
3,137
Last Week
16,727
Last Month
72,322
Last Year
972,089
GitHub Statistics
3 Stars
403 Commits
10 Forks
4 Watching
13 Branches
16 Contributors
Bundle Size
3.37 kB
Minified
1.11 kB
Minified + Gzipped
Package Meta Information
Latest Version
14.2.0
Package Id
@toruslabs/constants@14.2.0
Unpacked Size
30.65 kB
Size
5.32 kB
File Count
15
NPM Version
lerna/8.1.9/node@v20.16.0+arm64 (darwin)
Node Version
20.16.0
Publised On
26 Nov 2024
Total Downloads
Cumulative downloads
Total Downloads
1,321,569
Last day
-30%
3,137
Compared to previous day
Last week
-24.2%
16,727
Compared to previous week
Last month
-4.1%
72,322
Compared to previous month
Last year
178.2%
972,089
Compared to previous year
Daily Downloads
Weekly Downloads
Monthly Downloads
Yearly Downloads
Peer Dependencies
1
fetch-node-details
Introduction
This monorepo contains various packages to fetch node config of various web3auth's networks.
It has following pacakges:-
- @toruslabs/constants
- @toruslabs/fnd-base
- @toruslabs/fetch-node-details
- @toruslabs/fnd-server
Installation
- npm i
Run server
- npm run dev
Run test cases
- npm run test:ci
Build packages
- npm run build
![Empty State](/_next/static/media/empty.e5fae2e5.png)
No vulnerabilities found.
Reason
no dangerous workflow patterns detected
Reason
no binaries found in the repo
Reason
21 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Reason
license file detected
Details
- Info: project has a license file: LICENSE:0
- Info: FSF or OSI recognized license: MIT License: LICENSE:0
Reason
packaging workflow detected
Details
- Info: Project packages its releases by way of GitHub Actions.: .github/workflows/push_to_ecr.yaml:29
Reason
4 existing vulnerabilities detected
Details
- Warn: Project is vulnerable to: GHSA-r5w7-f542-q2j4
- Warn: Project is vulnerable to: GHSA-3xgq-45jj-v275
- Warn: Project is vulnerable to: GHSA-fc9h-whq2-v747
- Warn: Project is vulnerable to: GHSA-rhx6-c78j-4q9w
Reason
Found 6/12 approved changesets -- score normalized to 5
Reason
SAST tool is not run on all commits -- score normalized to 1
Details
- Warn: 3 commits out of 24 are checked with a SAST tool
Reason
detected GitHub workflow tokens with excessive permissions
Details
- Warn: no topLevel permission defined: .github/workflows/push_to_ecr.yaml:1
- Info: no jobLevel write permissions found
Reason
no effort to earn an OpenSSF best practices badge detected
Reason
project is not fuzzed
Details
- Warn: no fuzzer integrations found
Reason
security policy file not detected
Details
- Warn: no security policy file detected
- Warn: no security file to analyze
- Warn: no security file to analyze
- Warn: no security file to analyze
Reason
dependency not pinned by hash detected -- score normalized to 0
Details
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/push_to_ecr.yaml:35: update your workflow using https://app.stepsecurity.io/secureworkflow/torusresearch/fetch-node-details/push_to_ecr.yaml/master?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/push_to_ecr.yaml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/torusresearch/fetch-node-details/push_to_ecr.yaml/master?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/push_to_ecr.yaml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/torusresearch/fetch-node-details/push_to_ecr.yaml/master?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/push_to_ecr.yaml:75: update your workflow using https://app.stepsecurity.io/secureworkflow/torusresearch/fetch-node-details/push_to_ecr.yaml/master?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/push_to_ecr.yaml:78: update your workflow using https://app.stepsecurity.io/secureworkflow/torusresearch/fetch-node-details/push_to_ecr.yaml/master?enable=pin
- Warn: third-party GitHubAction not pinned by hash: .github/workflows/push_to_ecr.yaml:86: update your workflow using https://app.stepsecurity.io/secureworkflow/torusresearch/fetch-node-details/push_to_ecr.yaml/master?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/push_to_ecr.yaml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/torusresearch/fetch-node-details/push_to_ecr.yaml/master?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/push_to_ecr.yaml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/torusresearch/fetch-node-details/push_to_ecr.yaml/master?enable=pin
- Warn: containerImage not pinned by hash: Dockerfile.dev:1: pin your Docker image by updating node:20-alpine to node:20-alpine@sha256:2cd2a6f4cb37cf8a007d5f1e9aef090ade6b62974c7a274098c390599e8c72b4
- Warn: containerImage not pinned by hash: packages/fnd-server/Dockerfile:2
- Warn: containerImage not pinned by hash: packages/fnd-server/Dockerfile:22: pin your Docker image by updating node:20-alpine to node:20-alpine@sha256:2cd2a6f4cb37cf8a007d5f1e9aef090ade6b62974c7a274098c390599e8c72b4
- Warn: npmCommand not pinned by hash: Dockerfile.dev:11-15
- Warn: npmCommand not pinned by hash: packages/fnd-server/Dockerfile:15
- Warn: npmCommand not pinned by hash: .github/workflows/push_to_ecr.yaml:25
- Info: 0 out of 4 GitHub-owned GitHubAction dependencies pinned
- Info: 0 out of 4 third-party GitHubAction dependencies pinned
- Info: 0 out of 3 containerImage dependencies pinned
- Info: 1 out of 4 npmCommand dependencies pinned
Score
5.3
/10
Last Scanned on 2025-01-27
The Open Source Security Foundation is a cross-industry collaboration to improve the security of open source software (OSS). The Scorecard provides security health metrics for open source projects.
Learn More